Scenario playbooks

End-to-end operator narratives

Not single tools — full stories with intent, actions, expected results, pitfalls, and remediation. Run them in authorized labs and on networks you own.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

6 playbooks
beginner
2–4 hours4 steps

Compromised IoT camera on home Wi-Fi

Discover a camera, prove weak auth/RTSP exposure on hardware you own, contain it, and harden the LAN so a cam cannot reach trusted devices.

Open playbook
Scenario: You notice an unfamiliar device on the guest/main Wi-Fi. It turns out to be an IP camera (or a lab camera VM). Your job is to inventory it, …
beginner
2–3 hours4 steps

Exposed NAS share on the LAN

Find an open or weakly shared NAS/folder, prove data exposure without bulk theft, and lock down shares + network path.

Open playbook
Scenario: A home NAS or old PC share is visible to the whole LAN (or guest Wi-Fi). You will enumerate shares, demonstrate read access with minimal dat…
intermediate
half day4 steps

Web foothold → host privesc (lab)

Full narrative on an authorized lab box: map web app, gain RCE/file foothold, escalate on Linux, document each stage with fixes.

Open playbook
Scenario: A vulnerable lab web app (Juice Shop advanced chain, DVWA, Metasploitable service, or similar) is in your host-only network. You will treat …
beginner
1–2 hours4 steps

Close accidental WAN exposure

Discover what the internet can see on your public IP, shut down risky forwards, and replace remote access with VPN.

Open playbook
Scenario: After a home audit you suspect RDP, NAS, or camera ports might be reachable from WAN — or UPnP opened something you forgot. Confirm external…
intermediate
2–3 hours4 steps

Purple loop: noisy scan vs detection

Run a controlled Nmap/Hydra burst in lab, then find yourself in logs and write a detection note.

Open playbook
Scenario: You have an attacker VM and a target with logging (even simple auth.log + optional Wazuh/Suricata). Generate intentional noise, hunt it, and…
intermediate
3–5 hours4 steps

Password and auth lab narrative

From weak hash capture in lab to cracking methodology to online auth testing — with reporting that does not encourage reckless spraying.

Open playbook
Scenario: In an authorized lab you obtain password hashes (e.g., from a vulnerable app dump or Windows lab). You crack offline, analyze password quali…